Requesting Data Deletion
- Version
- 1
- Effective date
In short
If you want the data Atelye holds about you deleted, you can have it deleted. It is free, it does not require an account, and the quickest route for most people is a single email:
privacy@atelye.net — say that you want your data deleted, and tell us which business you were messaging.
The rest of this page explains the three routes in full, what actually gets deleted, the few things that do not, and how to check that it happened. It is written for someone who has never used Atelye and does not want to read a privacy policy.
First — who are we to you?
Atelye is a platform that businesses use to answer the messages their customers send them on Instagram, Facebook and WhatsApp, and to run their content and their online shop. It is operated by Murat Gözel, a sole trader in Türkiye. Atelye is the name of the product, not a company.
So we probably do not have a direct relationship with you. What we have is data that a business put into its account, or that reached us because you messaged that business and it uses Atelye to reply.
That matters for one reason only: for most requests, the business decides and we carry it out. We are not allowed to delete a business's records on our own initiative any more than a filing cabinet is allowed to empty itself. What we will not do is use that as an excuse — see If you do not hear back.
The three routes
Pick the one that matches your situation. If you are not sure, use Route 3 — email us and we will work it out.
Route 1 — Remove Atelye's access in your Instagram, Facebook or WhatsApp settings
Use this if you were asked at some point to connect your Instagram, Facebook or WhatsApp account to Atelye and you agreed — for example because you work with a business that uses it.
Do not use this if you simply sent a message to a business. In that case you never granted anything, there is nothing to remove, and Route 2 or Route 3 is what you want.
What to do:
- Open your settings on Facebook or Instagram.
- Find the section that lists the apps and websites you have given access to. On Facebook it is usually under Settings & privacy → Settings → Apps and websites; on Instagram it is under Settings → Website permissions or a similarly-named entry. Meta changes the wording from time to time, so look for the list of connected apps rather than an exact menu name.
- Find Atelye in the list and remove it.
What happens then: Meta tells us that you have withdrawn access. We treat that as a deletion request and act on it directly — we do not wait for anyone's permission, and we delete the data we hold about you across every business on the platform you have messaged, not just one. You do not have to contact us at all.
This is the one route where we act without asking the business first. That is deliberate: the request came from you, through the platform, and honouring it is our obligation.
You will be given a confirmation code so you can check the outcome. See Checking on your request.
Route 2 — Ask the business you were messaging
Use this if you messaged a business on Instagram, Facebook or WhatsApp and want that conversation deleted.
What to do: contact the business — the same account you messaged is fine — and tell them you want your data deleted. They can instruct us at any time, for one conversation, for a period of time, or for everything they hold about you.
What happens then: we act on their instruction. We do not overrule it, we do not delay it to the end of some retention period, and we do not charge them or you for it. A business's instruction to delete always takes priority over any default retention period we publish.
This is the primary route for most people, because the business is the one the law makes responsible for your data, and it is the one that actually knows who you are.
Route 3 — Email us
Use this if none of the above fits, if you cannot reach the business, or if you would simply rather deal with us.
What to do: email privacy@atelye.net. To help us find your data, tell us:
- which business you were messaging, if you know it;
- which channel you used — Instagram, Facebook or WhatsApp;
- the account, handle or phone number you messaged from; and
- what you want — deletion of everything, or of a particular conversation.
You do not need all of that. Send what you have.
What happens then: we acknowledge your email. If the data belongs to a business's account, we pass your request to that business, because it is their decision to make — and we tell you that we have done so, and we help them carry it out. If the data is ours to decide about — for example if you are a member of staff at a business that uses Atelye — we act on it ourselves.
We may need to check who you are before we delete anything, because deleting the wrong person's data on someone else's say-so would be its own kind of harm. We will ask for the least we can manage with, and we will not use anything you send us for that purpose for anything else.
What gets deleted
When a deletion runs, these are destroyed — not hidden, not marked deleted, not kept somewhere quieter:
- every message you sent and every reply sent to you, including the words themselves;
- every photo, video, voice note, document or other file in the conversation;
- every draft reply the AI produced about your message, and the record of any edits a person made to it;
- everything that was sent to an AI provider to produce those drafts, and everything it sent back;
- the raw data the messaging platform sent us;
- your entry in the search index, so you stop being findable inside the product; and
- anything still queued to be sent that mentions you.
Your identifier is destroyed too. The code the messaging platform uses to refer to you is overwritten with a meaningless random value. What is left is a record that a conversation happened — not whose. It cannot be turned back into you, and it cannot be matched to you by combining it with anything else we keep.
If you message the business again afterwards, you arrive as a genuinely new person. Nothing is resurrected.
What we keep, and why
Three things survive, and we would rather tell you than let you discover them.
1. A record that something happened, with nothing in it.
We keep an audit trail: that an action was taken, on which record, by which member of the business's staff, and when. After a deletion it contains no message content, no files and no identifier of yours. It says a conversation existed and was erased. It does not say what was in it.
We keep it because we have to be able to account for what the platform did — including proving that your deletion actually happened — and because it may be needed to establish or defend a legal claim. It is designed from the start to hold no personal content, which is exactly what makes a real deletion possible: if your words had been copied into a permanent audit record, deleting them would be impossible.
2. Counters.
Totals: how many messages a business handled in a month, what the AI cost it. Numbers, with nothing in them that points at you.
3. Backups — for a limited, fixed period.
Our database is backed up continuously so that we can recover from a disaster. Those backups have a 30-day point-in-time-recovery window, and full base copies are kept for up to 90 days.
A backup is a sealed snapshot of the whole database at a moment in time. It is not technically possible to reach inside one and cut a single person out of it — the attempt would corrupt the backup and leave us unable to recover from a real failure. So for up to 90 days after your data is erased from the live system, a copy may still exist inside a backup.
Here is what we commit to instead:
- backups are never opened or used except to recover from a disaster;
- they age out on the schedule above and are then gone; and
- if we ever do restore from one, we re-apply every completed deletion to the restored system before it serves anyone. A deletion you asked for does not come back to life because we had an outage.
How long it takes
We commit to completing a deletion within 30 days of receiving the request.
In practice it is much faster. A request that arrives through Route 1 is processed automatically and usually finishes in minutes. A request that arrives by email is read by a person first, which is why the commitment is measured in days rather than minutes.
If a deletion fails for any reason, it is recorded as failed and looked at. It is never quietly reported as done.
It is always free
We never charge for a deletion request. Not a fee, not an administrative cost, not a subscription, not an account. There is no route in which you have to pay, sign up or log in to have your data deleted.
You can also ask as many times as you like.
Checking on your request
A deletion request that reaches us through Route 1 gets a confirmation code.
A confirmation code is a random string of letters and numbers — something like a receipt number. It identifies the request and nothing else. It does not contain your name, your identifier or anything about you, and it cannot be used to look you up. Anyone who found it would learn only whether a request they cannot connect to a person had finished.
Enter it at /legal/data-deletion/status and you will see one of:
received— we have your request and it is queued.in progress— the deletion is running.completed— it is done.failed— something went wrong. We are looking at it; please contact us.
That page asks for the code and nothing else. No login, no name, no email address. Your code keeps working for 12 months after the request completes, and then stops.
Requests made through Route 2 or Route 3 do not produce a code — we reply to you by email instead, and you can ask us for confirmation at any point.
If you do not hear back
If you asked a business to delete your data and they have gone quiet, write to us anyway at privacy@atelye.net.
We will not hide behind "it is the business's decision". We will contact them, we will follow up, and where we are able to act ourselves, we will. Tell us what you asked for, roughly when, and who you asked.
Your other rights
Deletion is one of several rights you may have. You can also ask for a copy of your data, ask for it to be corrected, ask us to restrict what is done with it, or object to it being processed at all. The same routes apply, and the same 30-day commitment.
Full detail is in our Privacy Policy, including the section on Requesting data deletion.
If you are in the European Union or the European Economic Area, you also have the right to complain to your national data protection supervisory authority. We would rather you told us first — but it is your right, not our permission to give.
Contact
- Deletion requests, and anything about your personal data — privacy@atelye.net
- A security problem — security@atelye.net
- Anything else — support@atelye.net
Atelye is operated by Murat Gözel, sole proprietor, Türkiye. The full legal name, registered address and phone number are in the operator identity block at the foot of this page and at /contact.